Post Reply 
AOL pwned by script kiddy
Author Message
Ge64
Former Admin ;)

Posts: 3,163.4170
Threads: 295
Joined: 3rd Feb 2007
Reputation: 0.38918
E-Pigs: 108.4795
Offline
Post: #1
AOL pwned by script kiddy
Quote:A New York teenager broke into AOL networks and databases containing customer information and infected servers with a malicious program to transfer confidential data to his computer, AOL and the Manhattan District Attorney's Office allege.

In a complaint filed in Criminal Court of the City of New York, the DA's office alleges that between December 24, 2006 and April 7, 2007, 17-year old Mike Nieves committed offenses like computer tampering, computer trespass, and criminal possession of computer material.

Among his alleged exploits:

* Accessing systems containing customer billing records, addresses, and credit card information

* Infecting machines at an AOL customer support call center in New Delhi, India, with a program to funnel information back to his PC

* Logging in without permission into 49 AIM instant message accounts of AOL customer support employees

* Attempting to break into an AOL customer support system containing sensitive customer information

* Engaging in a phishing attack against AOL staffers through which he gained access to more than 60 accounts from AOL employees and subcontractors

Nieves faces four felony charges and one misdemeanor charge. He was arraigned on Monday and remains detained, a DA's office spokesman said. His next court date is Friday for a procedural hearing to determine the next step in the case, the spokesman said. Nieves' attorney didn't immediately return a call seeking comment.

The alleged acts cost AOL more than $500,000. It's not clear whether customer data was 'borrowed'. AOL declined to comment. The DA's office spokesman said the investigation into Nieves' alleged acts continues. "It's too early to tell exactly what [data] he compromised or not," he said.

The complaint states that Nieves admitted to investigators that he committed the alleged acts because AOL took away his accounts. "I accessed their internal accounts and their network and used it to try to get my accounts back," the defendant is quoted as saying in the complaint. He also admitted to posting photos of his exploits in a photo Web site, according to the complaint.

One doesn't have to be a computer genius to carry out the alleged acts thanks to the free availability of multiple hacking tools, said Mark Rasch, managing director of technology at FTI Consulting. "Even a disgruntled kid working alone can throw a virtual tantrum and cause a significant amount of damage to a large technology corporation," Rasch said. "Welcome to the new world."

If the defendant was honest about his motivation in his reported confession, it's safe to assume that he wasn't interested in stealing data for financial gain, Rasch said. Still, it'll be interesting to find out what steps AOL is taking if customer data was in fact compromised, he said.

There aren't enough facts available to judge whether AOL could have done more to prevent the alleged intrusion. "Wee'll learn more as the case goes on," he said. "AOL has had pretty good security over the years."

Authorities arrested Nieves after AOL provided them with information from an internal investigation into the alleged acts. AIM subscriber information and IP address data involved in the acts led AOL to Nieves, whose address and phone number AOL had on file, according to the complaint.

The New York Post reported Thursday that Nieves lives in Staten Island and quoted his mother as saying that he is a special education student with behavioral problems. An anonymous source told the Post that Nieves has caused AOL problems for years.

A source close to the investigation told IDG News Service that Nieves is allegedly part of a "loosely coupled" group of hackers who have targeted AOL and other companies in recent years, but that Nieves focused specifically on hacking into AOL.

- Source: [infoworld or somet]

[Image: ub1985584.jpg]
(This post was last modified: 28/04/2007 03:20 AM by Ge64.)
28/04/2007 03:18 AM
Find all posts by this user Quote this message in a reply
dedat
I also poo when hungry.

Posts: 1,319.1315
Threads: 32
Joined: 14th Apr 2007
Reputation: 1.65351
E-Pigs: 3.5147
Offline
Post: #2
RE: AOL pwnt by script kiddy
wow, how did he manage that one?
28/04/2007 03:29 AM
Find all posts by this user Quote this message in a reply
ZiNgA BuRgA
Smart Alternative

Posts: 17,022.2988
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.1294
Offline
Post: #3
RE: AOL pwnt by script kiddy
Lol, he's smart computer wise, but dumb otherwise.
28/04/2007 03:50 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Ge64
Former Admin ;)

Posts: 3,163.4170
Threads: 295
Joined: 3rd Feb 2007
Reputation: 0.38918
E-Pigs: 108.4795
Offline
Post: #4
RE: AOL pwnt by script kiddy
he probly knew he'd be arrested and didnt care. he probably liked the publicity. dyu what kind of job it could get him if he puts this on his CV? big companies pay big money for ppl like this

[Image: ub1985584.jpg]
28/04/2007 04:54 AM
Find all posts by this user Quote this message in a reply
dedat
I also poo when hungry.

Posts: 1,319.1315
Threads: 32
Joined: 14th Apr 2007
Reputation: 1.65351
E-Pigs: 3.5147
Offline
Post: #5
RE: AOL pwnt by script kiddy
yeah, they probably would, youd rather have a talented hacker working for you rather then against you..
that's why sony should hire DarK_AleX lol...;P
28/04/2007 04:56 AM
Find all posts by this user Quote this message in a reply
ZiNgA BuRgA
Smart Alternative

Posts: 17,022.2988
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.1294
Offline
Post: #6
RE: AOL pwnt by script kiddy
Ge64 Wrote:he probly knew he'd be arrested and didnt care. he probably liked the publicity. dyu what kind of job it could get him if he puts this on his CV? big companies pay big money for ppl like this
I don't think companies hire criminals...

They probably won't hire him - they could get hacked after all...
28/04/2007 05:07 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Ge64
Former Admin ;)

Posts: 3,163.4170
Threads: 295
Joined: 3rd Feb 2007
Reputation: 0.38918
E-Pigs: 108.4795
Offline
Post: #7
RE: AOL pwnt by script kiddy
lol
i wonder what would be more difficult, hacking AOL and gaining access to basicly everything, or hacking a psp's firmware... i know what would have more impact lol
Double post
ZiNgA BuRgA Wrote:
Ge64 Wrote:he probly knew he'd be arrested and didnt care. he probably liked the publicity. dyu what kind of job it could get him if he puts this on his CV? big companies pay big money for ppl like this
I don't think companies hire criminals...

They probably won't hire him - they could get hacked after all...

microsoft has already hired mountains of hackers for beta testing
it has proven to be efficient
and if they work for you its much easier to track them down lol...

[Image: ub1985584.jpg]
28/04/2007 05:11 AM
Find all posts by this user Quote this message in a reply
amzter
The bird stole my shoe.

Posts: 1,830.3066
Threads: 342
Joined: 3rd May 2007
Reputation: -4.56241
E-Pigs: 54.7074
Offline
Post: #8
RE: AOL pwnt by script kiddy
matey is going to jail for a looooooooooooooooooooooooooong time.
what i don't get is that why don't they jus hire him so he can imporve there security like that guy who broke into the pentagon they should hire him

[Image: 494851774.png]
Search:
04/05/2007 12:12 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Forum Jump:


User(s) browsing this thread: 3 Guest(s)

 Quick Theme: